Principal Appsec Engineer

Super · Spain · Engineering

Posted 2026-09-28

Apply for this role →

Product Security is responsible for preventing vulnerabilities before code ships, absorbing on-demand security-testing load, and making security testing part of everything that reaches production. This role owns the team's deep offensive capability, running adversary emulation and bypass testing against production systems and providing the technical depth behind the team's hardest architecture reviews. Reporting to the Product Security Lead, the Principal AppSec Engineer sets the bar for pentest quality that engineers execute against.

What the role involves

Run adversary emulation and bypass testing against production systems to identify exploitable weaknesses.

Own the standardised pentest playbooks used for urgent "launching next week" requests and personally handle the highest-complexity engagements.

Lead in-depth architecture and design reviews for high-risk features, threat-modelling before code is written and producing security requirements and sign-off.

Mature and scale AI-assisted pentest tooling (e.g. NEO, regression code scanning) to increase testing coverage.

Mentor less experienced AppSec engineers in pentest methodology and adversarial thinking.

Feed confirmed bypass and pentest findings to Detection Engineering & Threat Hunting so each becomes a shipped detection.

Contribute to the vendor security testing element of the shared vendor intake process for high-risk vendors.

What we are looking for

6+ years' experience in offensive security — pentesting, red teaming, or adversary emulation — ideally including production/live-environment experience.

Strong architecture review skills, with the ability to threat-model a system from a design document rather than only testing a finished build.

Familiarity with the modern AppSec tooling landscape (SAST/DAST, AI-assisted pentest tools).

Comfortable acting as the technical escalation point for the team's hardest problems.

Nice to have

Experience running or contributing to bug bounty triage or vulnerability-disclosure programmes.

What we offer

Medical / Health Insurance

Open Annual Leave

Employee Assistance Programme

Training & Learning Development

Apply for this role →

← Back to all jobs